Quick Start baselines
Deploy a complete OpenIntuneBaseline platform pack in one step, with a backup first and a one click undo.
Quick Start deploys a complete OpenIntuneBaseline (OIB) platform pack into a tenant in one step. TenuVault backs up the tenant first, then creates every policy of the pack under its OIB name next to your existing policies. Each run can be undone: Undo deletes exactly the objects that run created.
OpenIntuneBaseline is published by SkipToTheEndpoint and contributors under the GPL-3.0 license. TenuVault downloads the policy files from the upstream GitHub repository when you use them; they are not bundled with the app.
Where to find it
Section titled “Where to find it”Open Frameworks in the sidebar and select OpenIntuneBaseline. The Quick Start section is at the top of the page. The tenant it deploys to is the one selected in the sidebar.
What your plan includes
Section titled “What your plan includes”| Community | Pro | MSP | |
|---|---|---|---|
| Windows pack, tested release | Yes | Yes | Yes |
| macOS, Windows 365 and BYOD app protection packs | No | Yes | Yes |
| Other OIB releases | No | Yes | Yes |
| Also deploy to other connected tenants | No | No | Yes |
On Community, the section header shows “Community: tested Windows release”, and other platforms and releases carry a Pro badge. On Pro and MSP it shows “All platforms and releases”.
Requirements
Section titled “Requirements”- The tenant is signed in and licensed.
- The tenant has backup storage chosen. Quick Start always backs up before deploying. Without storage, the section shows “Choose where backups for this tenant are stored in Settings first. Quick Start always backs up before deploying.” See Choose where backups are stored.
- Your account has an Intune role that can create the policy types in the pack.
- The device can reach
api.github.comandraw.githubusercontent.com. See Network connections and data flows.
Platforms and releases
Section titled “Platforms and releases”| Platform button | Pack | Tested release |
|---|---|---|
| Windows | OIB Windows | v3.8 |
| macOS | OIB macOS | v1.0 |
| Windows 365 | OIB Windows 365 | v1.0 |
| BYOD app protection | OIB BYOD app protection policies for iOS and Android | Pinned commit |
The Release list shows the tested release, marked “(tested)”, followed by newer OIB releases for the platform that TenuVault finds on GitHub. If GitHub cannot be reached, only the tested release is offered, with a note that starts “Only the tested release is available:”.
A pack can contain Settings Catalog policies, compliance policies, device configuration profiles, update policies, driver update profiles and app protection policies, depending on the platform.
Deploy a pack
Section titled “Deploy a pack”- Select a platform and a Release.
- Click Preview pack. TenuVault downloads the pack and lists its policies by type, with a count for each. Expand a type to see the policy names.
- Optional: enter a Pilot group object ID. See Unassigned or pilot group.
- Optional, MSP only: under Also deploy to, tick other connected tenants.
- Click Back up and deploy (or Back up and deploy to N tenants).
- Confirm the dialog. It states what happens, for example: “Back up tenant and then create N policies from release, unassigned? Existing policies stay unchanged.”
While the run is in progress, the status line shows the current stage: loading the pack, backing up the tenant, checking existing policies, then “Creating policy name” with a count.
What happens during a run
Section titled “What happens during a run”- Backup. TenuVault runs a full backup of the tenant to its configured storage and waits for it to finish. If the backup cannot start, fails, or takes longer than an hour, the run stops and nothing is deployed.
- Existing policy check. TenuVault reads the tenant’s existing policies of each type in the pack. A policy that already exists with the same type and name is left unchanged and reported as skipped, so running a pack twice does not create duplicates.
- Creation. Every remaining policy is created under its OIB name. Assignments stored in the source files are ignored; Quick Start decides assignments itself.
Only one Quick Start deployment or undo can run per tenant at a time.
Unassigned or pilot group
Section titled “Unassigned or pilot group”“Policies are created unassigned unless you give a pilot group; nothing reaches devices until a policy is assigned. With a pilot group, every policy is assigned to that Entra group only.”
- Leave Pilot group object ID empty to create all policies unassigned. Review them in Intune, then assign them yourself.
- Enter an Entra group object ID (a GUID) to assign every created policy to that group. An invalid value shows “Enter a group object ID (GUID).” Assigned policies reach the group’s devices at their next check-in.
Deploy to several tenants (MSP)
Section titled “Deploy to several tenants (MSP)”Also deploy to deploys the same pack to other connected tenants after the selected tenant, one tenant at a time:
- Each tenant is backed up first to its own storage.
- In other tenants, policies are always created unassigned. The pilot group applies to the selected tenant only.
- A tenant without backup storage shows “No backup storage, will be skipped” and is reported as “Skipped: no backup storage is chosen for this tenant in Settings, and Quick Start always backs up first.”
- A failure in one tenant is reported for that tenant, and the next tenant continues.
- Each tenant’s own plan is checked.
Read the results
Section titled “Read the results”Each tenant gets a result card, for example “N completed, N already in the tenant and left unchanged from release.” The card also shows:
- Backup taken first: the name of the backup folder created before the deployment. You can restore from it if needed.
- Whether the policies were assigned to the pilot group or left unassigned.
- One line per policy: “created”, “incomplete, retained for undo” (a follow-up step such as assignments failed), or the error for failed policies.
Failed writes follow the same safety rules as restores. A write with an unknown outcome is not repeated automatically; resolve it in Settings > Storage and recovery > Restore write history. See Restore write history.
Undo a run
Section titled “Undo a run”Every run is saved on this device, including interrupted runs, so it can be undone.
- Click Undo this run on the result card, or Undo next to a run under Previous runs.
- Confirm “Delete the N policies created by release in tenant on date? Only objects this run created are deleted.”
- The result shows how many policies were removed. Policies that were already deleted count as removed.
Undo never touches policies the run did not create, and never touches policies that were skipped because they already existed. If some deletions fail, the remaining objects stay in the run so you can retry Undo or delete them in Intune.
Previous runs lists up to 20 recent runs for the selected tenant with their release, date and how many policies are left to undo. A run with nothing left to undo is removed from the list.
Quick Start compared with gap analysis
Section titled “Quick Start compared with gap analysis”Quick Start deploys whole packs. To compare your existing Settings Catalog policies with a baseline setting by setting, and create only the missing settings, use Framework coverage.
Troubleshooting Quick Start
Section titled “Troubleshooting Quick Start”| Message | Cause and fix |
|---|---|
| GitHub request failed (403) … GitHub limits requests per network; retry later. | GitHub rate limits unauthenticated requests per network. Wait and retry, or use another network. |
| Only the tested release is available: … | GitHub could not be reached, so newer releases are not listed. The tested release still works if the policy files can be downloaded. |
| The backup could not start, so nothing was deployed. | Check the tenant’s sign-in, license and backup storage, then retry. |
| The backup failed, so nothing was deployed. | Open Backup & Restore and check the backup log. Fix the cause and retry. |
| The backup did not finish within an hour, so nothing was deployed. | Retry at a quieter time, or check the backup log for slow types. |
| Existing type could not be read (status). Nothing was created. | Check your Intune role and the app registration permissions. |
| A Quick Start deployment or undo is already running for this tenant. | Wait for the current run to finish. |
| This Quick Start run was already undone or is not recorded on this device. | Runs are stored per device. Delete leftover policies in Intune. |
| The pilot group must be an Entra group object ID. | Enter the group’s object ID (GUID), not its name. |
License and attribution
Section titled “License and attribution”OpenIntuneBaseline content is by SkipToTheEndpoint and contributors and licensed under GPL-3.0. Keep that attribution and license when you share policy content from the pack.